THE STRATEGY
1. Establishing a Resilient cyber ecosystem in Afghanistan
a) Information Systems Security Directorate (ISSD) of Ministry of Communications and
Information Technologies (MCIT) to coordinate all cyber and information security
related issues in the country with clearly defined roles and responsibilities. Having had
the privilege of managing AFCERT since its establishment, ISSD should become an
independent entity within Government structure once it reaches its maturity levels.
This will avoid every kind of unwanted and unwarranted influence from other
government and nongovernment entities on cybersecurity tasks and decisions ensuring ISSD’s full integrity.
b) Encourage both public and private sector to assign a member of senior management as
Chief Security Officer (CSO), giving them the responsibility of cybersecurity efforts
and initiatives in the country, ensuring public private partnership.
c) Encourage both public and private sectors to draft and develop their information
security policies aligned with their business profile and services in compliance with
international standards and best practices. Policies should be comprehensive, up to
date with various data security methodologies, include Disaster Recovery Plan and
business continuity.
d) Both public and private sectors to dedicate budget for cyber and information security
activities and initiatives. The budget should be for the overall cybersecurity initiatives
including IT infrastructure protection mechanisms, licensed software, patches and
capacity building for IT personnel.
e) AFCERT to serve both public and private sectors as a first responder to cyber and
computer incidents, given its professional staff and good reputation AFCERT will also
work together with both sectors in order to establish mini and provincial CERTs for
better coordination of the cybersecurity agenda, AFCERT will make sure that all
entities adapt to and abide by the AFCERT assigned procedures and best practices in
the field of incident response, cyber/computer crime scene data collection.
f) MCIT from security point of view will certify and approve any IT related procurement
within the government, MCIT will come up with new guidelines and policies for the
webhosting companies, software developers and IT services provider.
2. Establishing a framework for information safety, assurance, information security
policies
a) ISSD of MCIT should enforce the adaptation of international standards, information
security best practices, and compliance in order to ensure Confidentiality,
Accessibility and Integrity of information throughout government networks.
Information
Systems
Security
Directorate
-‐
MCIT